osquery

osquery · osquery.osquery

SQL powered operating system instrumentation, monitoring, and analytics.

winget install --id osquery.osquery --exact --source winget

Latest 5.23.0

Release Notes

What's Changed Features

  • Add process memory scanning capability to yara table by @brian-mckinney in #8782
  • Split yara tables into yara_process and yara_file by @brian-mckinney in #8835
  • Add Windows process_open_handles table by @brian-mckinney in #8795
  • Add secureboot_certificates table for Linux by @zwass in #8844
  • Extend python_packages and npm_packages to cover modern package managers by @ariary in #8801
  • Add level filtering to the unified_log table by @directionless in #8788
  • Disallow newlines in curl custom headers by @directionless in #8787
  • Supplement LaunchServices with directory scanning in apps table (#8789) by @getvictor in #8790
  • Command line flags for query input and output by @directionless in #8786
  • New header-based authentication mechanism for remote APIs by @juan-fdz-hawa in #8805
  • Add recursion to npm_packages by @directionless in #8809
  • Make profile.py performance thresholds configurable via CLI flags by @stefanamaerz in #8841
  • Add ROOT\default to WMI tables by @directionless in #8810 Build & Dependencies
  • Update expat to 2.7.4 to fix CVE-2026-25210 by @Sampriti2803 in #8794
  • Fix GCC 15 compatibility by @carlsmedstad in #8837 Fixes
  • Fix macOS keychain corruption when accessing non-SSV keychain files by copying to temporary files first by @lucasmrod in #8840
  • Fix incorrect example queries in table specs by @edwardsb in #8791
  • Improve network_name detection on macOS wifi_status table by @lucasmrod in #8781
  • Fix a bug in apt_sources parsing by @directionless in #8785
  • Add NOCASE and VERSION collation to various columns by @directionless in #8813
  • Increase the limit on systemd unit iteration by @directionless in #8802
  • Fix format string vulnerability in shell.cpp disconnect_socket() by @directionless in #8824
  • Fix saving file times in file carves by @zwass in #8819
  • Fix empty results from office_mru table by @thierryfranzetti in #8838
  • Fix multiple security vulnerabilities in smc_keys.cpp by @directionless in #8820
  • Fix gatekeeper table on macOS 15+ by @thierryfranzetti in #8831
  • Fix container bounds checking vulnerabilities by @directionless in #8825
  • Reduce noisy logs from chrome_extensions by @lucasmrod in #8792 New Contributors
  • @edwardsb made their first contribution in #8791
  • @Sampriti2803 made their first contribution in #8794
  • @ariary made their first contribution in #8801
  • @juan-fdz-hawa made their first contribution in #8805
  • @thierryfranzetti made their first contribution in #8838
  • @stefanamaerz made their first contribution in #8841 Full Changelog: 5.22.1...5.23.0

Installer type: wix

Architecture Scope Download SHA256
x64 Download 5060C7CC21BC00258B5D7822A769CB619FF432C02BA89F6C1B6CBFA127D59B40

Details

Homepage
https://osquery.io/
License
Apache-2.0 OR GPL-2.0-only
Publisher
osquery
Support
https://github.com/osquery/osquery/issues

Tags

hacktoberfestintrusion-detectionmonitoringsecuritysql

Older versions (10)

5.22.1
Architecture Scope Download SHA256
x64 Download 91238C6F7543979E59D88886D61E8E7A222F6595F89B24BFAC385D31433F7A02
5.21.0
Architecture Scope Download SHA256
x64 Download 573E53F9C5E8BE3B356CAB1CD1A4C4BB175E811B89BE7AD89D04AFAC8527B464
5.20.0
Architecture Scope Download SHA256
x64 Download 68BC735B82AEB7AF8660A770B6626BE2ADBA5403E8112C62BAB254BA5B917960
5.19.0
Architecture Scope Download SHA256
x64 Download 6FE06CAB43A31C596E4001616EEE66FB32556BF5C228C4A4BA6DAF2897EDC1A3
5.18.1
Architecture Scope Download SHA256
x64 Download BA4C5DEF84E35EF101FC4EC3F47DD2124C66D736F0F124ACDB18C7B29DF253FE
5.17.0
Architecture Scope Download SHA256
x64 Download AF3CD2F989F7F7ACA667291674EDA4656F7795A7559F47E72521E71B31FF3BA5
5.16.0
Architecture Scope Download SHA256
x64 Download BE40425E0E4C182F9A1B882FC12A8B81FA4E872D3CD27AAD62AEE0CD1FAC7038
5.11.0
Architecture Scope Download SHA256
x64 Download 825BF75D0DCA88A5E8CEA699B90696738BD9BE44C9B8CFCE3906A3E2AB49B156
5.8.2
Architecture Scope Download SHA256
x64 Download D319837D4E95D1E477C2126D383501180925A29F488FF1164FA16D2E576F96DD
5.6.0
Architecture Scope Download SHA256
x64 Download C480B7B0352FB19B952DF9C0331926F134B1234DA716C8B12B6A9C5E19CABCE9